CWE-125 跨界内存读 类弱点 3492 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-125 越界读取属于内存安全漏洞,指程序访问了缓冲区边界之外的内存区域。攻击者利用此缺陷可读取敏感数据或引发信息泄露,甚至通过特定构造触发逻辑错误以辅助后续攻击。开发者应严格实施边界检查,确保索引在有效范围内,并使用支持自动边界检测的高级语言或静态分析工具,从源头杜绝非法内存访问。
int getValueFromArray(int *array, int len, int index) { int value; // check that the array index is less than the maximum // length of the array if (index < len) { // get the value at the specified index of the array value = array[index]; } // if array index is invalid then output error message // and return value indicating error else { printf("Value is: %d\n", array[index]); value = -1; } return value; }
... // check that the array index is within the correct // range of values for the array if (index >= 0 && index < len) { ...
int processMessageFromSocket(int socket) { int success; char buffer[BUFFER_SIZE]; char message[MESSAGE_SIZE]; // get message from socket and store into buffer //Ignoring possibliity that buffer > BUFFER_SIZE if (getMessage(socket, buffer, BUFFER_SIZE) > 0) { // place contents of the buffer into message structure ExMessage *msg = recastBuffer(buffer); // copy message body into string for processing int index; for (index = 0; index < msg->msgLength; index++) { message[index] = msg->msgBody[index]; } message[index] = '\0'; // process message success = processMessage(message); } return success; }
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-56210 | AOMedia libaom 缓冲区错误漏洞 — Red Hat Enterprise Linux AI 3.3 for RHEL 9 | 7.1 | High | 2026-06-19 |
| CVE-2026-48138 | NI grpc-device 缓冲区错误漏洞 — grpc-device | 7.5 | High | 2026-06-19 |
| CVE-2025-15661 | libssh2 缓冲区错误漏洞 — libssh2 | 6.5 | Medium | 2026-06-18 |
| CVE-2026-56099 | OpenBSD 缓冲区错误漏洞 — src | 5.3 | Medium | 2026-06-18 |
| CVE-2026-50643 | Rui Ueyama 8cc 缓冲区错误漏洞 — 8cc | - | - | 2026-06-18 |
| CVE-2026-30802 | RTI Connext Micro 缓冲区错误漏洞 — Connext Micro | - | - | 2026-06-17 |
| CVE-2026-3894 | RTI connext professional 缓冲区错误漏洞 — Connext Professional | - | - | 2026-06-17 |
| CVE-2026-48142 | F5 Nginx Plus 缓冲区错误漏洞 — NGINX Open Source | 4.8 | Medium | 2026-06-17 |
| CVE-2026-12461 | Google Chrome 缓冲区错误漏洞 — Chrome | - | - | 2026-06-17 |
| CVE-2026-12444 | Google Chrome 缓冲区错误漏洞 — Chrome | - | - | 2026-06-17 |
| CVE-2026-47748 | leejet stable-diffusion.cpp 缓冲区错误漏洞 — stable-diffusion.cpp | 5.5 | Medium | 2026-06-16 |
| CVE-2026-4367 | X.Org libXpm 安全漏洞 — Red Hat Hardened Images | 5.5 | Medium | 2026-06-16 |
| CVE-2026-47963 | Adobe DNG SDK 缓冲区错误漏洞 — Adobe DNG Software Development Kit (SDK) | 5.5 | Medium | 2026-06-16 |
| CVE-2026-47934 | Adobe DNG SDK 缓冲区错误漏洞 — Adobe DNG Software Development Kit (SDK) | 5.5 | Medium | 2026-06-16 |
| CVE-2026-47927 | Adobe DNG SDK 缓冲区错误漏洞 — Adobe DNG Software Development Kit (SDK) | 5.5 | Medium | 2026-06-16 |
| CVE-2026-1765 | GNOME localsearch 安全漏洞 — Red Hat Enterprise Linux 10 | 5.6 | Medium | 2026-06-16 |
| CVE-2026-1764 | GNOME localsearch MP3 Extractor 安全漏洞 — Red Hat Enterprise Linux 10 | 5.6 | Medium | 2026-06-16 |
| CVE-2026-12087 | PEVANS Socket 缓冲区错误漏洞 — Socket | - | - | 2026-06-15 |
| CVE-2026-53704 | gstreamer project RealMedia demuxer 缓冲区错误漏洞 — Red Hat Enterprise Linux 10.0 Extended Update Support | 7.1 | High | 2026-06-15 |
| CVE-2026-53703 | GStreamer RealMedia demuxer 缓冲区错误漏洞 — Red Hat Enterprise Linux 10 | 7.1 | High | 2026-06-15 |
| CVE-2026-52721 | GStreamer 缓冲区错误漏洞 — Red Hat Enterprise Linux 10 | 5.3 | Medium | 2026-06-15 |
| CVE-2026-52719 | GStreamer gst-plugins-bad VA JPEG decoder 缓冲区错误漏洞 — Red Hat Enterprise Linux 10 | 7.1 | High | 2026-06-15 |
| CVE-2026-54412 | Liam Bindle MQTT-C 缓冲区错误漏洞 — MQTT-C | 8.2 | High | 2026-06-14 |
| CVE-2025-9033 | Gen Digital Avira Antivirus 缓冲区错误漏洞 — Avira Antivirus | 7.8 | High | 2026-06-12 |
| CVE-2025-9032 | Gen Digital Avira Antivirus 缓冲区错误漏洞 — Avira Antivirus | 7.8 | High | 2026-06-12 |
| CVE-2025-7017 | Gen Digital Avira Antivirus 缓冲区错误漏洞 — Avira Antivirus | 7.8 | High | 2026-06-12 |
| CVE-2025-7011 | Gen Digital Avast Antivirus 缓冲区错误漏洞 — Avast Antivirus | 7.8 | High | 2026-06-12 |
| CVE-2025-7009 | Gen Digital Avast Antivirus 缓冲区错误漏洞 — Avast Antivirus | 7.8 | High | 2026-06-12 |
| CVE-2025-7008 | Gen Digital Avast Antivirus 缓冲区错误漏洞 — Avast Antivirus | 7.8 | High | 2026-06-12 |
| CVE-2025-7003 | Gen Digital Avira Antivirus 缓冲区错误漏洞 — Avira Antivirus | 7.8 | High | 2026-06-12 |
CWE-125(跨界内存读) 是常见的弱点类别,本平台收录该类弱点关联的 3492 条 CVE 漏洞。